Description
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NEDB-1305279
Related Vulnerabilities
CVE-2021-4231 Vulnerability in npm package @angular/core
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-font
CVE-2021-40690 Vulnerability in maven package org.apache.santuario:xmlsec
CVE-2021-4264 Vulnerability in maven package org.webjars.bower:dustjs-linkedin
CVE-2021-41151 Vulnerability in npm package @backstage/plugin-scaffolder-backend